GHSA-4pgp-q8h4-9wxmHighCVSS 7.5
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an...
🔗 CVE IDs covered (1)
📋 Description
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns_provider_credentials value is interpolated directly into a shell command executed via child_process.exec() without sanitization or escaping, causing the injected command to execute upon backend restart.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-40519
- https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5498
- https://github.com/NginxProxyManager/nginx-proxy-manager/commit/a5db5ed156355e3088e7d1ceb0533d4bae922def
- https://www.vulncheck.com/advisories/nginx-proxy-manager-authenticated-rce-via-setupcertbotplugins
- https://github.com/advisories/GHSA-4pgp-q8h4-9wxm